skip to main content
10.1145/1242572.1242655acmconferencesArticle/Chapter ViewAbstractPublication PageswwwConference Proceedingsconference-collections
Article

Subspace: secure cross-domain communication for web mashups

Published:08 May 2007Publication History

ABSTRACT

Combining data and code from third-party sources has enabled a new wave of web mashups that add creativity and functionality to web applications. However, browsers are poorly designed to pass data between domains, often forcing web developers to abandon security in the name of functionality. To address this deficiency, we developed Subspace, a cross-domain communication mechanism that allows efficient communication across domains without sacrificing security. Our prototype requires only a small JavaScript library, and works across all major browsers. We believe Subspace can serve as a new secure communication primitive for web mashups.

References

  1. Vikram Agrawal. TODO List. http://googlemodules.com/module/612/.Google ScholarGoogle Scholar
  2. Richard Cornford. JavaScript Closures, March 2004. http://jibbering.com/faq/faq_notes/closures.html.Google ScholarGoogle Scholar
  3. D. Crockford. JSONRequest. http://www.json.org/jsonrequest.html.Google ScholarGoogle Scholar
  4. Flickr Services API. http://www.flickr.com/services/api/.Google ScholarGoogle Scholar
  5. C. Fournet and A. D. Gordon. Stack Inspection: Theory and Variants. In Symposium on Principles of Programming Languages, 2001. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. Web Hypertext Application Technology Working Group. Web Applications 1.0, February 2007. http://www.whatwg.org/specs/web-apps/current-work/.Google ScholarGoogle Scholar
  7. ECMA International. Standard ECMA-262, December 1999.Google ScholarGoogle Scholar
  8. C. Jackson, A. Bortz, D. Boneh, and J. Mitchell. Protecting Browser State Against Web Privacy Attacks. In Proc. WWW, 2006. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. T. Powell and F. Schneider. JavaScript: The Complete Reference. McGraw-Hill/Osborne, second edition. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. C. Reis, J. Dunagan, H. J. Wang, O. Dubrovsky, and S. Esmeir. BrowserShield: Vulnerability-Driven Filtering of Dynamic HTML . In Proc. OSDI, 2006. Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. J. Ruderman. JavaScript Security: Same Origin. http://www.mozilla.org/projects/security/components/same-origin.html.Google ScholarGoogle Scholar
  12. W3C. Authorizing Read Access to XML Content Using the <?access-control?> Processing Instruction 1.0. http://www.w3.org/TR/access-control/, May 2006.Google ScholarGoogle Scholar

Index Terms

  1. Subspace: secure cross-domain communication for web mashups

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Conferences
          WWW '07: Proceedings of the 16th international conference on World Wide Web
          May 2007
          1382 pages
          ISBN:9781595936547
          DOI:10.1145/1242572

          Copyright © 2007 ACM

          Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 8 May 2007

          Permissions

          Request permissions about this article.

          Request Permissions

          Check for updates

          Qualifiers

          • Article

          Acceptance Rates

          Overall Acceptance Rate1,899of8,196submissions,23%

          Upcoming Conference

          WWW '24
          The ACM Web Conference 2024
          May 13 - 17, 2024
          Singapore , Singapore

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader